Privacy Policy

Display Units: Wholesale B2B · Last updated: 12 August 2026

Display Units: Wholesale B2B is provided by Skylight Media ("we", "us"). Contact: apps@skylightmedia.co.uk

Who this covers

Two groups:

For any buyer data, the merchant is the data controller and we act as their processor. We handle buyer data only on the merchant's behalf and only to provide the app. In practice the app stores no buyer-identifying data in its records — see "What we process about buyers" below.

What we collect from merchants

Subscription and payment

The app is paid for by subscription. Billing is handled entirely by Shopify App Pricing (the plan is configured in Shopify's Partner Dashboard and Shopify hosts the plan-selection page): the merchant approves the charge inside their Shopify admin, Shopify takes payment through the merchant's existing Shopify account, and it appears on their Shopify invoice.

We never see or store payment card details, bank details or billing addresses. The app reads only whether a store has an active subscription and which plan, in order to decide whether to let the admin through.

Support correspondence

The app's "Need support?" link opens a message in the merchant's own email program, addressed to us, with their store domain filled in. Nothing is sent through the app itself, and nothing is sent until the merchant presses send in their own email program. Once they do, we aim to respond within 48 hours and hold that correspondence in our mailbox for 30 days.

What we process about buyers

The app stores no buyer-identifying data in its records.

When a trade buyer uses the on-store configurator to fill a display, the app records an anonymous build: which package it is, which products were chosen and in what quantity, and a random build identifier. This lets Shopify charge the single fixed package price for the finished display, and lets the buyer return later to edit their selection. A build is not linked in our records to the buyer's name, email, customer account, company or order — it carries nothing that identifies a person.

For completeness: when a signed-in buyer opens the configurator, Shopify includes that buyer's Shopify customer ID in the request it sends the app. The app does not read, use or store this ID — it is never recorded against a build — though it may appear transiently in the app's server request logs. We request no other buyer data from Shopify: no names, email addresses, phone numbers, postal addresses, customer accounts, companies or orders. We do not collect payment details; payments are handled by Shopify.

Why we process it

That is the whole of it. We run no analytics, we do not tag or read orders, we do not use buyer data for marketing, we do not sell or share it, we build no profiles, and we make no automated decisions about individuals.

Tracking, cookies and browser storage

The app sets no tracking cookies and runs no analytics scripts on storefronts. The buyer-facing configurator uses JavaScript only to operate the interface — counting selections and updating the display. We do not observe buyers who do not build a display.

It does use two pieces of storage on the buyer's own device, both strictly necessary to provide the feature the buyer has asked for, and neither used to track anyone:

Because both are strictly necessary for a service the buyer has actively requested, they fall within the exemption in the UK Privacy and Electronic Communications Regulations and do not require a consent banner. We mention them because they are storage on a device, and we would rather be explicit than technically silent.

Where data is held

In a PostgreSQL database hosted by Neon, and on application servers hosted by Fly.io, both in the United Kingdom (London). Data is encrypted in transit and at rest.

Subprocessors

ProviderPurposeLocation
NeonDatabase hostingUnited Kingdom (London)
Fly.ioApplication hostingUnited Kingdom (London)
ShopifyThe merchant's own platform, where the app runs

How long we keep it

Buyer rights

Because the app stores no buyer-identifying data in our records, we hold nothing to return in response to an access request and nothing to erase on a redaction request. Buyers should still contact the merchant they ordered from — the merchant is the controller and owns that relationship. Shopify provides merchants with tools to request or erase customer data, and we act on those requests automatically.

Rights under UK and EU data protection law include access, rectification, erasure, restriction, portability and objection.

Security

Changes

We will update this policy when the app's data handling changes, and update the date above. Material changes will be communicated to merchants.

Contact: apps@skylightmedia.co.uk

If you are in the UK and unsatisfied with our response, you may complain to the Information Commissioner's Office (ico.org.uk).